VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,754)

page 29 of 88
  • CVE-2010-4226HigFeb 6, 2014
    risk 0.47cvss 7.2epss 0.03

    cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.

  • CVE-2026-55074HigSep 21, 2026
    risk 0.46cvss —epss —

    Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and ran mkdir -p and mv there as root on the…

  • CVE-2026-83999HigSep 8, 2026
    risk 0.46cvss 7.0epss 0.00

    Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-69379HigSep 8, 2026
    risk 0.46cvss 7.0epss 0.00

    Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-66153HigAug 25, 2026
    risk 0.46cvss 7.0epss 0.00

    The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.

  • CVE-2026-16989HigAug 20, 2026
    risk 0.46cvss 7.1epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links.

  • CVE-2026-19693HigAug 17, 2026
    risk 0.46cvss 8.1epss 0.00

    extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file…

  • CVE-2026-70460HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.00

    rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under…

  • CVE-2026-63426HigAug 13, 2026
    risk 0.46cvss 7.1epss 0.00

    During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.

  • CVE-2026-53795HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.00

    rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve…

  • CVE-2026-53783HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.00

    rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation…

  • CVE-2026-15994HigAug 13, 2026
    risk 0.46cvss 7.0epss 0.00

    During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.

  • CVE-2026-12036HigAug 13, 2026
    risk 0.46cvss 7.1epss 0.00

    An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.

  • CVE-2026-73613HigAug 13, 2026
    risk 0.46cvss 8.2epss 0.00

    filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope. Attackers can swap an ancestor directory…

  • CVE-2026-72694HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path,…

  • CVE-2026-50526HigJul 14, 2026
    risk 0.46cvss 7.0epss 0.00

    Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

  • CVE-2026-6851HigJul 14, 2026
    risk 0.46cvss 7.0epss 0.00

    An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by leveraging a race conditions via Symbolic…

  • CVE-2026-54371HigJun 29, 2026
    risk 0.46cvss 7.1epss 0.00

    attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a…

  • CVE-2026-54369HigJun 29, 2026
    risk 0.46cvss 7.1epss 0.00

    acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a…

  • CVE-2026-54230HigJun 13, 2026
    risk 0.46cvss 7.0epss 0.00

    A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows…